Skip to content
Saturday, June 27, 2026
  • Splunk Enterprise RCE Shows SIEM Servers Are Tier-Zero Infrastructure
  • NAIC Breach Shows Why PeopleSoft Internet Exposure Needs Immediate Review
  • Hospitality Photo-ZIP Campaign Shows Front Desk Workflows Are Initial Access Paths
  • CL-STA-1062 Shows Critical Infrastructure Intrusions Still Start With Web Shells
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
  • Splunk Enterprise RCE Shows SIEM Servers Are Tier-Zero Infrastructure
  • NAIC Breach Shows Why PeopleSoft Internet Exposure Needs Immediate Review
  • Hospitality Photo-ZIP Campaign Shows Front Desk Workflows Are Initial Access Paths
  • CL-STA-1062 Shows Critical Infrastructure Intrusions Still Start With Web Shells
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
Recent
  • Editorial cybersecurity illustration of a SIEM data pipeline and server infrastructure under attack, representing Splunk Enterprise CVE-2026-20253 defensive hardening.

    Splunk Enterprise RCE Shows SIEM Servers Are Tier-Zero Infrastructure

    11 hours ago
  • Editorial cybersecurity illustration of Oracle PeopleSoft exploitation and defensive monitoring around regulatory data systems

    NAIC Breach Shows Why PeopleSoft Internet Exposure Needs Immediate Review

    15 hours ago
  • Editorial cybersecurity illustration of a hotel front desk system targeted by photo ZIP phishing and Node.js implant activity.

    Hospitality Photo-ZIP Campaign Shows Front Desk Workflows Are Initial Access Paths

    20 hours ago
  • Editorial cyber threat intelligence illustration for CL-STA-1062, TinyRCT, and critical infrastructure intrusion defense.

    CL-STA-1062 Shows Critical Infrastructure Intrusions Still Start With Web Shells

    1 day ago
  • Editorial cybersecurity illustration representing Turla STOCKSTAY WebSocket command-and-control and government espionage activity.

    Turla’s STOCKSTAY Backdoor Shows Why Espionage Defense Needs Egress Visibility

    2 days ago
  • Editorial cybersecurity illustration of SharkLoader malware and Cobalt Strike intrusion activity

    StrikeShark Shows Loader Malware Is an Edge-Exposure Problem

    2 days ago
  • Editorial cyber threat intelligence illustration of MuddyWater using ransomware branding as a false flag.

    MuddyWater’s Chaos Masquerade Shows Ransomware Response Needs Attribution Discipline

    2 days ago
  • Editorial CTI illustration of Operation Endgame disrupting SocGholish malware infrastructure across compromised websites.

    SocGholish Takedown Shows Website Trust Is Malware Infrastructure

    6 days ago
  • Editorial cybersecurity illustration of Operation Escaneo targeting Latin American edge infrastructure and critical networks.

    Operation Escaneo Shows Latin America’s Edge Devices Are Prime Intrusion Targets

    7 days ago
  • Abstract cybersecurity illustration of an AI software supply-chain compromise affecting package dependencies and developer pipelines.

    Mastra npm Compromise Shows AI Frameworks Are Supply-Chain Targets

    7 days ago
  • General CTI

WinRAR CVE-2025-8088: Russia, China, and Cybercriminals Unite to Exploit Path Traversal Flaw

acint5 months ago02 mins

Google Threat Intelligence reveals widespread exploitation of CVE-2025-8088 by Russian APT groups, Chinese actors, and cybercriminals. The WinRAR path traversal flaw enables payload delivery via the Windows Startup folder, with active campaigns targeting Ukraine, LATAM, and financial sectors.

Read More
  • North Korean Cyber Threat Intelligence

North Korean Konni APT Deploys AI-Generated Malware to Target Blockchain Developers

acint5 months ago5 months ago02 mins

The North Korean threat group Konni has launched a new campaign using AI-generated PowerShell malware to target blockchain developers across the APAC region, marking a significant shift toward technical targets and cryptocurrency infrastructure.

Read More
  • General CTI

Microsoft to Disable 30-Year-Old NTLM Authentication Protocol by Default

acint5 months ago5 months ago02 mins

Microsoft announces NTLM will be disabled by default in upcoming Windows releases, marking the end of the 30-year-old authentication protocol that has been a persistent security vulnerability.

Read More
  • Operational Technology (OT)

CVE-2026-24061: 11-Year-Old GNU Telnetd Vulnerability Grants Instant Root Access

acint5 months ago03 mins

CVE-2026-24061 is a critical 11-year-old vulnerability in GNU InetUtils telnetd that allows unauthenticated attackers to gain instant root shell access. With a CVSS score of 9.8 and active exploitation confirmed, this flaw affects over 200,000 devices running Telnet servers globally, including embedded systems, IoT devices, and OT infrastructure.

Read More
Mobile device security concept with digital vulnerabilities
  • General CTI

Ivanti Patches Two Critical EPMM Zero-Day Vulnerabilities Under Active Exploitation

acint5 months ago02 mins

Two critical CVSS 9.8 vulnerabilities in Ivanti Endpoint Manager Mobile (CVE-2026-1281, CVE-2026-1340) are under active exploitation, allowing unauthenticated remote code execution. CISA has added them to the KEV catalog with a February 1 federal deadline.

Read More
  • General CTI

Ivanti EPMM Zero-Days Actively Exploited: Pre-Auth RCE via Bash Arithmetic Expansion

acint5 months ago5 months ago02 mins

Two actively exploited pre-auth RCE vulnerabilities (CVE-2026-1281 and CVE-2026-1340) in Ivanti Endpoint Manager Mobile allow attackers to execute arbitrary commands via Bash arithmetic expansion. CISA has added these to the KEV catalog.

Read More
  • Malware

Android Malware Campaign Abuses Hugging Face AI Platform to Distribute RAT

acint5 months ago5 months ago02 mins

Threat actors are abusing the Hugging Face AI platform to host Android malware, using server-side polymorphism to generate thousands of RAT variants every 15 minutes.

Read More
  • General CTI

SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score

acint5 months ago02 mins

SmarterTools patches critical CVE-2026-24423 (CVSS 9.3) unauthenticated RCE vulnerability in SmarterMail email server. Two other flaws including one under active exploitation also addressed. Update immediately.

Read More
  • Business

Aisuru Botnet Shatters Records with 31.4 Tbps DDoS Attack

acint5 months ago5 months ago02 mins

The Aisuru/Kimwolf botnet launched the largest DDoS attack ever publicly disclosed, peaking at 31.4 Tbps and 200 million requests per second in Cloudflare’s ‘Night Before Christmas’ campaign.

Read More
  • Business

Match Group Data Breach Exposes User Information from Tinder, Hinge, and OkCupid

acint5 months ago02 mins

Match Group confirms cybersecurity incident after ShinyHunters voice phishing campaign compromises SSO account, exposing data from popular dating apps including Tinder, Hinge, OkCupid, and Match.com.

Read More
  • 1
  • …
  • 27
  • 28
  • 29
  • 30
  • 31
  • …
  • 37

File Search

2
ThumbNameSizeDate
Thumb IOCs_YARA_TTPs_Posted_Articles/ IOCs_YARA_TTPs_Posted_Articles

IOCs_YARA_TTPs_Posted_Articles

Open 99.71 KB 2024-01-12 January 12, 2024 2024-03-22 March 22, 2024
21 Items
99.71 KB
March 22, 2024

0

0bd2c4ab56

2026 Powered By BlazeThemes.